← Back to blog

All the deadlines of Law 21.719: key dates and when it takes effect.

The quick reference with every date that matters: from when oversight begins to the time limit for responding to a rights request or notifying a breach. Keep it on hand so you never miss a deadline.

Deadlines · Law 21.719
Short answer

Chile's Law 21.719 comes into force on 1 December 2026. From that date the operational deadlines run: 30 calendar days to answer a rights request, extendable once by 30 more (article 11), and breach reporting to the Agency without undue delay (article 14 sexies). A bill now before the Senate would move that date to 2027, but the enforceable date is still December 2026.

The essentials in 30 seconds

  • Publication: December 13, 2024.
  • Entry into force and oversight: December 1, 2026.
  • Adjustment period: 24 months (that is the time you have to implement).
  • ARSOP rights: response within the legal time limit (30 calendar days, extendable once by 30 more).
  • Breaches: notification to the Agency without undue delay, by the most expedient means.

"When does it take effect?" is the question that comes up most often — but it is not the only date that matters. Once the law is mandatory, the clock starts running every time a customer exercises a right or a breach occurs. This is the table with every deadline in one place. If you want the full picture, start with the definitive guide to Law 21.719. If you want the full picture, start with our guide to the data protection law in Chile.

All deadlines and key dates

Every Law 21.719 deadline with the article that sets it
Milestone or dutyExact deadlineBasis
Publication of the law in the Official Gazette13 December 2024Law 21.719
Entry into force and start of enforcement1 December 2026, first day of the twenty-fourth month after publicationFirst transitory article
Issuance of the law's regulationsWithin six months of publicationSecond transitory article
First appointment of the Agency's BoardSix months before entry into forceFourth transitory article
Acknowledgement and reply to a rights request30 calendar days from receipt, extendable once by up to 30 more calendar daysArticle 11
Reply to a temporary blocking request2 business days from receiptArticle 11
Data subject's claim before the Agency after a refusal30 business daysArticles 11 and 41
Reporting a breach to the AgencyWithout undue delay, by the most expedient means availableArticle 14 sexies
Communicating the breach to data subjectsRequired only where it affects sensitive data, data of children under fourteen, or economic, financial, banking or commercial dataArticle 14 sexies
Adopting corrective measures after a sanction60 days; otherwise a 50% surcharge is added to the fineArticle 35
Transitory window for smaller enterprisesFirst twelve months in force: the Agency may issue a written warningSixth transitory article
Limitation period to pursue infringements4 years from the occurrence of the actArticle 40
Limitation period for imposed sanctions3 years from the decision becoming finalArticle 40
Entries in the sanctions registerKept for the period the law sets, with free public accessArticle 39

What happens on December 1, 2026?

It is the date on which the Personal Data Protection Agency can begin to audit and impose sanctions. The law was published in December 2024 and granted a 24-month adjustment period precisely so organizations would arrive prepared. That window is running out: in practice, adjustment projects take between 1 and 6 months depending on size, so the time to start is before the deadline, not on it.

Since 1 September 2026 the Senate has been considering a bill that would move that date to 1 December 2027 and expand the Agency's Board from three to five members. It is a bill, not a law: until it is published in the Official Gazette, the enforceable date is still 1 December 2026. Planning around an extension that does not yet exist is the risk, not the precaution.

Deadlines to respond to rights (ARSOP)

Once the law is in force, any person may exercise their rights of Access, Rectification, Erasure, Objection and Portability. The organization must respond within the legal time limit of 30 calendar days. The problem is usually not the deadline itself, but not having a channel or a procedure ready when the first request arrives. We walk through the full flow —identity verification, exceptions and templates— in how to respond to ARSOP rights requests.

Deadlines in the event of a security breach

In the face of an incident affecting personal data, notification to the Agency must be made without undue delay and by the most expedient means possible. The law does not set a fixed number of hours; the 72-hour figure is an international best-practice benchmark. In addition, you must communicate to the affected individuals when the breach involves sensitive data, data of children and adolescents, or economic and financial data. That is why it pays to have the procedure rehearsed before you need it.

Why it does not pay to wait

Several compliance actions —contracts with processors, consent management, security measures— depend on third parties and on implementation time. Reaching December 1, 2026 with a documented plan under way, even if not everything is closed, demonstrates proactive accountability and serves as a mitigating factor. If you want to organize the work by area, use the compliance checklist.

Will you make it in time for December 1, 2026?

A 30-minute assessment tells you how much is left and in what order to move forward. No obligation.

Book an assessment

Frequently asked questions

When does Law 21.719 take effect?

It was published on December 13, 2024, and becomes fully mandatory on December 1, 2026, after a 24-month adjustment period. From that date the Personal Data Protection Agency may audit and impose sanctions.

How long is the adjustment period under Law 21.719?

24 months, counted from publication (December 13, 2024) until oversight begins (December 1, 2026). It is the time to implement compliance.

What is the deadline to respond to ARSOP rights?

Within the legal time limit of 30 calendar days, extendable once by up to 30 more. That is why it is essential to have a defined channel and procedure in place before the requests arrive.

What is the deadline to notify a security breach?

To the Agency, without undue delay and by the most expedient means possible. To affected individuals, when the breach involves sensitive data, data of children and adolescents, or economic and financial data.

Why does Law 21.719 come into force precisely on 1 December 2026?

Because the first transitory article of Law 21.719 sets entry into force on the first day of the twenty-fourth month after its publication in the Official Gazette. Published on 13 December 2024, that calculation lands on 1 December 2026. It is not a discretionary date and the Agency cannot postpone it.

Is the deadline to answer rights requests in business or calendar days?

Calendar days. Article 11 of Law 21.719 requires the controller to acknowledge receipt and rule no later than thirty calendar days from the request being filed, extendable once by up to thirty further calendar days. Counting them as business days is the most common error in Chile.

Is there a 72-hour breach notification deadline in Chile?

No. The 72 hours belong to article 33 of the European GDPR. Article 14 sexies of Law 21.719 requires reporting to the Agency "by the most expedient means available and without undue delay", without fixing a number of hours. In practice that standard is stricter, not looser.

What is the deadline to answer a temporary blocking request?

Two business days from receipt, under article 11 of Law 21.719. Until it rules, the controller may not process the data covered by the request. Blocking does not affect storage, and if the request is refused the reply must be reasoned and communicated electronically to the Agency.

How long does a data subject have to claim before the Agency?

Thirty business days. Article 11 of Law 21.719 requires the controller to state that deadline to the data subject when refusing a request in whole or in part, and the procedure follows article 41. The same period runs where the controller simply fails to reply within the thirty calendar days.

When do infringements and sanctions become time-barred?

Article 40 of Law 21.719 sets four years for actions pursuing liability, counted from the occurrence of the act, and three years for sanctions already imposed, counted from the decision becoming final. For continuing infringements the period runs from the day the infringement ceased.

Official sources

This article is for information purposes only and does not constitute legal advice for a specific case.

You may also be interested in

Legislation

The Law 21.719 regulation: what it covers and where it stands

Sanctions

Fines and sanctions under Law 21.719: how much and why

Compliance

Law 21.719 compliance checklist: the 10 areas to close

Law 21.719

Law 21.719: the definitive guide to comply and avoid multimillion-dollar fines

Next step

Is your company ready
for December 2026?

30-minute assessment, no obligation.

Request an assessment